Privacy Policy
Last updated: August 28, 2026
Applies to: the CaptchaSonic browser extension (Chrome Web Store item ID dkkdakdkffippajmebplgnpmijmnejlh), the CaptchaSonic API, and captchasonic.com.
CaptchaSonic is a CAPTCHA-solving assistant. To solve a challenge, the extension must send limited information about the page containing that challenge to our solving service. This policy describes exactly what is collected, when, why, who it is shared with, and how long it is kept.
1. Summary of data collected by the extension
| Data | Collected when | Why | Where it goes | Retention |
|---|---|---|---|---|
| Website URL / visited URL (full page URL of the page containing the CAPTCHA) | Only when a supported CAPTCHA is detected and a solve is attempted | Many CAPTCHA providers bind a token to the page URL; the solve fails without it | api.captchasonic.com | 30 days |
| Host name / domain (e.g. example.com) | Only when a solve is attempted | Aggregate CAPTCHA-solving reliability metrics, so we can detect and fix solvers that break on a given site | access.captchasonic.com (our self-hosted analytics) | 30 days |
| CAPTCHA website key / site key | Only when a solve is attempted | Required by the CAPTCHA provider to generate a valid token | api.captchasonic.com | 30 days |
| CAPTCHA challenge content — the challenge images, canvas/video frames, and the challenge question text rendered inside the CAPTCHA widget | Only when a solve is attempted | This is the puzzle our model solves | api.captchasonic.com | Deleted after the solve completes; retained up to 7 days only if flagged for accuracy review |
| Device fingerprint — a SHA-256 hash derived from canvas, WebGL, and audio rendering signals plus user agent, platform, language(s), CPU core count, device memory, touch points, color depth, screen resolution and time zone | Once per device, refreshed periodically | Security and abuse prevention, including detecting unauthorized API-key sharing, credential resale, automated abuse, and fraudulent use of prepaid credits | api.captchasonic.com | Duration of the account, then 90 days |
| Device ID (random identifier generated on install) | On install | Ties usage to a single installation for rate limiting | api.captchasonic.com | Duration of the account |
| API key and account username/email | When you enter your API key | Authentication and credit accounting | api.captchasonic.com | Duration of the account |
| Technical context — extension version, browser user agent, browser language, screen dimensions, event timestamps | With each solve event | Debugging and compatibility | access.captchasonic.com | 30 days |
| Error diagnostics — error message and a truncated stack trace (max 500 characters) | Only on a failed solve | Bug fixing | access.captchasonic.com | 30 days |
1.1 Service usage data
- API Logs: We retain API request logs for up to 30 days to troubleshoot errors and verify usage counts.
- Account Metadata: Email address and billing history are stored securely for account management.
- Payment Data: All financial transactions are processed by PCI-DSS compliant third parties (e.g., Stripe, Triple-A). We do not store full credit card or crypto wallet private keys.
1.2 What the extension does not collect
- We do not collect your general browsing history. No webpage URL, host name, page content, or CAPTCHA data is transmitted from pages where no supported CAPTCHA is being processed. The content script loads on all sites solely to detect CAPTCHA widgets, and it stays silent otherwise. The device fingerprint and device ID described above are account-level anti-abuse identifiers: they contain no URL and no page content, and they are not a record of the pages you visit.
The extension may technically access webpage URL and host information while inspecting pages for supported CAPTCHA widgets; however, this information is transmitted to our servers only when required to process a CAPTCHA-solving request. Access for detection and transmission to our servers are separate things, and only the latter results in any data leaving your browser.
- We do not read, collect, or transmit page content outside the CAPTCHA widget — no form fields, no passwords, no page text, no cookies, no full-page screenshots.
- We do not collect keystrokes, clipboard contents, financial information, health information, or personal communications.
- We do not use the collected data for advertising, ad targeting, credit scoring, or lending.
- We do not sell, rent, trade, or transfer your data to third parties for their own purposes.
2. Why the extension needs access to websites
CaptchaSonic's single purpose is to detect and solve supported CAPTCHA challenges. CAPTCHAs can appear on websites across the internet, so the extension requires broad website access to detect supported CAPTCHA widgets wherever they appear.
The extension does not use this access to collect general browsing history, track websites visited, or build advertising profiles. URL and host information is transmitted only when required to process a CAPTCHA-solving request.
3. Legal basis (GDPR)
- Performance of a contract (Art. 6(1)(b)) — website URL, site key and CAPTCHA challenge content: the service cannot be delivered without them.
- Legitimate interests (Art. 6(1)(f)) — device fingerprint, device ID, error diagnostics and CAPTCHA-solving reliability metrics, for fraud prevention, abuse prevention and service reliability. You may object at any time via [email protected].
- Contract / legitimate interests — account email and billing records.
4. Sharing and service providers
Data collected by the extension is primarily processed on CaptchaSonic-operated infrastructure at api.captchasonic.com and access.captchasonic.com.
We do not sell, rent, or provide collected extension data to third parties for their independent purposes.
Payment Data: All financial transactions are processed by PCI-DSS compliant third parties (e.g., Stripe, Triple-A). We do not store full credit card or crypto wallet private keys.
Our analytics are self-hosted on our own infrastructure. We do not use Google Analytics or any third-party advertising or tracking SDK in the extension.
We may also disclose data where required by a valid, legally binding subpoena or court order, or to protect the rights, property or safety of CaptchaSonic, our users, or the public.
5. Retention and deletion
Website URLs (visited URLs) and host names associated with CAPTCHA-solving requests are retained for up to 30 days for the purposes described in this policy, including service operation, security, troubleshooting, and CAPTCHA-solving reliability.
Other retention periods are listed in the data collection table in Section 1.
Account records are kept while the account is active and deleted within 30 days of a deletion request, except where a longer period is required by law or for fraud investigation.
6. Your rights
Depending on your location (GDPR, UK GDPR, CCPA/CPRA and similar laws) you have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent. Exercise any of these by emailing [email protected]; we respond within 30 days.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA. See our Do Not Sell or Share My Personal Information page. We honor the Global Privacy Control (GPC) signal on captchasonic.com.
7. Security and data handling
- All extension-to-server traffic is encrypted with TLS 1.3.
- Backups are encrypted at rest with AES-256.
- API keys are stored locally in the browser extension storage and transmitted only to api.captchasonic.com.
- Automated threat detection guards against unauthorized access.
8. Chrome Web Store User Data Policy compliance
CaptchaSonic's use and transfer of user data received through the Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use user data only as necessary to provide, secure, maintain, and improve the extension's disclosed CAPTCHA-solving functionality.
9. Cookies and tracking on captchasonic.com
Essential storage is always on; analytics and marketing storage stay off until you opt in. The full breakdown is in our Cookie Policy.
If your browser broadcasts the Global Privacy Control (GPC) signal, we automatically opt you out of analytics and marketing storage and persist that choice.
10. Children
CaptchaSonic is not directed at children under 13 (under 16 in the EEA) and we do not knowingly collect their data.
11. Changes
Material changes to this policy will be announced on captchasonic.com and reflected in the "Last updated" date above.
12. Contact
- Privacy: [email protected]
- Support: [email protected]